Cyberpanel

Cyberpanel

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.53%
  • Veröffentlicht 10.05.2026 13:16:31
  • Zuletzt bearbeitet 13.05.2026 15:29:03

CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager controller endpoint. Attackers can manipulate the comp...

Exploit
  • EPSS 0.77%
  • Veröffentlicht 24.04.2026 20:40:36
  • Zuletzt bearbeitet 28.04.2026 15:44:53

CyberPanel versions prior to 2.4.4 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/s...

Exploit
  • EPSS 0.5%
  • Veröffentlicht 24.04.2026 20:40:12
  • Zuletzt bearbeitet 28.04.2026 15:45:19

CyberPanel versions prior to 2.4.4 contain a stored cross-site scripting vulnerability in the AI Scanner dashboard where the POST /api/ai-scanner/callback endpoint lacks authentication and allows unauthenticated attackers to inject malicious JavaScri...

  • EPSS 0.24%
  • Veröffentlicht 16.12.2024 06:15:07
  • Zuletzt bearbeitet 05.09.2025 00:30:15

CyberPanel (aka Cyber Panel) before f0cf648 allows XSS via token or username to plogical/phpmyadminsignin.php.

Exploit
  • EPSS 10.76%
  • Veröffentlicht 16.12.2024 04:15:05
  • Zuletzt bearbeitet 05.09.2025 00:33:27

CyberPanel before 2.3.8 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the phpSelection field to the websites/submitWebsiteCreation URI.

Exploit
  • EPSS 0.91%
  • Veröffentlicht 05.12.2024 14:15:22
  • Zuletzt bearbeitet 05.09.2025 13:39:46

CyberPanel (aka Cyber Panel) before 6778ad1 does not require the FilemanagerAdmin capability for restartMySQL actions.

Warnung Medienbericht Exploit
  • EPSS 94.88%
  • Veröffentlicht 29.10.2024 23:15:04
  • Zuletzt bearbeitet 07.11.2025 19:02:54

getresetstatus in dns/views.py and ftp/views.py in CyberPanel (aka Cyber Panel) before 1c0c6cb allows remote attackers to bypass authentication and execute arbitrary commands via /dns/getresetstatus or /ftp/getresetstatus by bypassing secMiddleware (...

Warnung Medienbericht Exploit
  • EPSS 86.73%
  • Veröffentlicht 29.10.2024 23:15:04
  • Zuletzt bearbeitet 07.11.2025 19:02:50

upgrademysqlstatus in databases/views.py in CyberPanel (aka Cyber Panel) before 5b08cd6 allows remote attackers to bypass authentication and execute arbitrary commands via /dataBases/upgrademysqlstatus by bypassing secMiddleware (which is only for a ...

Exploit
  • EPSS 45.68%
  • Veröffentlicht 29.10.2024 23:15:04
  • Zuletzt bearbeitet 07.07.2025 16:17:23

CyberPanel (aka Cyber Panel) before 2.3.5 allows Command Injection via completePath in the ProcessUtilities.outputExecutioner() sink. There is /filemanager/upload (aka File Manager upload) unauthenticated remote code execution via shell metacharacter...

Exploit
  • EPSS 0.84%
  • Veröffentlicht 02.07.2019 16:15:12
  • Zuletzt bearbeitet 21.11.2024 04:24:07

An issue was discovered in CyberPanel through 1.8.4. On the user edit page, an attacker can edit the administrator's e-mail and password because of the lack of CSRF protection.